← Home

unocss

36
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

antfuunocss-botzyyv

Keywords

unocssatomic-cssatomic-css-enginecsstailwindwindicss

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from antfu to GitHub Actions CI/CD publishing with SLSA provenance; stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Active project with 442 versions; dormancy gap is an artifact of the publisher change, not abandonment. ai
source-diff obfuscated-file:dist/index-XUBLdNw_.d.mts AI (source-diff): Bundled TypeScript declaration file with readable types; not obfuscated. ai
source-diff source-size-tripled AI (source-diff): Size increase from bundling declarations into single file; normal for this package's build change. ai
dependencies unvetted-dep:@unocss/astro AI (dependencies): @unocss/astro is a first-party sub-package of the unocss monorepo, pinned to the same version. Not a third-party risk. ai
dependencies unvetted-dep:@unocss/postcss AI (dependencies): @unocss/postcss is a first-party sub-package of the unocss monorepo, pinned to the same version. Not a third-party risk. ai
dependencies unvetted-dep:@unocss/preset-icons AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-wind3 AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-wind4 AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-tagify AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-web-fonts AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-typography AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/cli AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/transformer-directives AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/transformer-compile-class AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/transformer-variant-group AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/transformer-attributify-jsx AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
phantom-deps phantom-dep:@unocss/cli AI (phantom-deps): CLI tool referenced in config rather than directly imported; normal pattern for monorepo umbrella packages. ai
dependencies unvetted-dep:@unocss/preset-attributify AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/core AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/vite AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-uno AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-mini AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai
dependencies unvetted-dep:@unocss/preset-wind AI (dependencies): First-party @unocss/* sub-package at matching version; part of the UnoCSS monorepo umbrella structure. ai

Versions (showing 36 of 36)

Version Deps Published
66.7.0 17 / 3
66.6.8 17 / 3
66.6.7 17 / 3
66.6.6 17 / 3
66.6.5 17 / 3
66.6.4 17 / 3
66.6.2 17 / 3
66.6.1 17 / 3
66.6.0 19 / 2
66.5.12 19 / 2
66.5.11 19 / 2
66.5.10 19 / 2
66.5.9 19 / 2
66.5.7 19 / 2
66.5.6 19 / 2
66.5.5 19 / 2
66.5.4 19 / 2
66.5.3 19 / 2
66.5.2 19 / 2
66.5.1 19 / 2
66.5.0 19 / 2
66.4.2 19 / 2
66.4.1 19 / 2
66.4.0 19 / 2
66.3.3 19 / 2
66.3.2 19 / 2
66.3.1 19 / 2
66.2.3 19 / 2
66.2.2 19 / 2
66.2.1 19 / 2
66.2.0 19 / 2
66.1.4 19 / 2
66.1.3 19 / 2
66.1.2 19 / 2
66.1.1 19 / 2
66.1.0 19 / 2

v66.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.12

2 findings
HIGH New obfuscated file: dist/index-XUBLdNw_.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.11

2 findings
HIGH New obfuscated file: dist/index-XUBLdNw_.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.4

2 findings
HIGH Publisher changed: antfu → GitHub Actions (on 2025-10-15) provenance

This version was published by a different npm account than previous versions on 2025-10-15. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.3

2 findings
HIGH Publisher changed: antfu → GitHub Actions (on 2025-10-10) provenance

This version was published by a different npm account than previous versions on 2025-10-10. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.2

2 findings
HIGH Publisher changed: antfu → GitHub Actions (on 2025-09-23) provenance

This version was published by a different npm account than previous versions on 2025-09-23. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v66.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.